Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareKillDisk | KillDisk has called |
| T1083 File and Directory Discovery |
MalwareKillDisk | KillDisk has used the |
| T1134 Access Token Manipulation |
MalwareKillDisk | KillDisk has attempted to get the access token of a process by calling |
| T1489 Service Stop |
MalwareKillDisk | KillDisk terminates various processes to get the user to reboot the victim machine. |
| T1529 System Shutdown/Reboot |
MalwareKillDisk | KillDisk attempts to reboot the machine by terminating specific processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.